A flaw was found in the Curl package, where the HSTS mechanism would be ignored by subsequent transfers when done on the same command line because the state would not be properly carried. This issue may result in limited confidentiality and integrity.
Platform | Package | Release Date | Advisory |
---|---|---|---|
Amazon Linux 2 - Core | curl | 2023-03-02 22:36 | ALAS2-2023-1986 |
Amazon Linux 2023 | curl | 2023-02-21 16:43 | ALAS2023-2023-114 |
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv3 | 3.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N |
NVD | CVSSv3 | 9.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |